Pairwise DID Permission Delegation via Cryptographic Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Centralized identity management systems are burdensome and prone to fraud in delegating permissions, requiring manual processes that lack security and efficiency.
Innovation Solution
A decentralized system using pairwise DIDs allows computing systems to securely and automatically delegate permission scopes between DID owners based on relationships, utilizing cryptographic technologies and distributed ledgers to record and validate these delegations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized identity management systems are used for permission delegation, then security is maintained through centralized control, but the system becomes burdensome and prone to fraud with manual processes
Solution Approach 1:
The patent replaces manual mechanical processes with automated cryptographic systems. Permission delegations are automatically verified using cryptographic proofs and blockchain validation, eliminating manual identity verification processes while maintaining security through decentralized cryptographic authentication mechanisms
Solution Approach 2:
The patent introduces blockchain as an intermediary layer that mediates between identity providers and permission requesters. The blockchain network validates permission delegations through distributed consensus and cryptographic verification, removing the need for centralized identity management intermediaries while enhancing security through decentralization
2Ease of operation
If centralized identity management systems are used, then identity verification can be performed, but the system requires intermediaries that reduce privacy and increase complexity
Solution Approach 1:
The patent extracts the identity verification function from centralized identity management systems and relocates it to the decentralized blockchain network. Individual users maintain their own identity credentials off-chain, while the blockchain only stores and verifies cryptographic proofs, separating identity data storage from verification functionality and reducing centralized infrastructure complexity
Solution Approach 2:
The patent enables users to self-manage their identity credentials and permission delegations without centralized control. Users generate their own cryptographic key pairs, store credentials in personal wallets, and autonomously verify permission proofs, eliminating the need for centralized identity management infrastructure while simplifying the overall system architecture
3Productivity
If manual permission delegation processes are used, then centralized control is maintained, but security is reduced and efficiency is lowered
Solution Approach 1:
The patent replaces manual permission delegation processes with automated cryptographic verification. Permission proofs are cryptographically generated and automatically validated by the blockchain network, eliminating manual review processes while enhancing security through cryptographic immutability and distributed validation
Solution Approach 2:
The patent implements preliminary cryptographic binding between identity credentials and permission scopes. Permission delegations are pre-signed with cryptographic keys and anchored to the blockchain before actual access is needed, enabling instant verification and execution without manual approval processes while maintaining security through pre-established cryptographic trust
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Delegating a scope of permission between pairwise DIDs. First, a computing system determines a relationship between the first DID and a second DID. The first DID and the second DID are pairwise DIDs. Based on the relationship, the computing system delegates a scope of permission owned by the first DID to the second DID. In particular, the computing system defines the scope of permission, grants a public key of the second DID the scope of the permission. The delegation of the defined scope of permission is signed by a private key of the first DID, such that the signature is a proof of the delegation. A portion of data related to the delegation is then propagated onto the distributed ledger.